Explore MetaDefender Software Supply Chain
MetaDefender Software Supply Chain brings repository, container, binary, and file scanning into one place. Connect the services you already use, automate security checks, investigate risks, and take action from a unified view.
Detect risks across the software supply chain
Apply multiple security technologies to the files and artifacts in your software supply chain:
Malware and other threats: use MetaScan multiscanning to inspect files with multiple anti-malware engines.
Exposed secrets: detect credentials, tokens, and other sensitive data committed to source code or included in artifacts.
Open source vulnerabilities: generate a Software Bill of Materials (SBOM) and identify known vulnerabilities in dependencies.
License risks: surface open source license information to support policy and compliance reviews.
Workflows show which technologies are active for a scan and let you define how results are handled.
Scan from development to delivery
You can also use the CLI Scanner to bring file and directory scanning into command-line workflows and CI/CD pipelines.
Automate security checks
Choose the scan method that matches each development workflow:
Start an on-demand scan for one or more repositories and references.
Create scheduled scans that run hourly, daily, weekly, or monthly.
Configure event-based scanning to respond to repository changes.
Enable hash scanning to skip unchanged files and focus repeat scans on new or modified content.
Use Jobs to create scans and monitor active, upcoming, and completed work.
Turn findings into action
The Dashboard summarizes risk across all scanned repositories and highlights the packages and repositories that need attention. Security suggestions identify package updates that can resolve vulnerabilities.
Detailed Reports let you move from the overall picture to individual repositories, packages, files, and CVEs. Export results when you need to share findings or continue analysis outside the product.
Custom workflows add policy and remediation controls. Depending on the service and artifact type, a workflow can keep, copy, soft-delete, or delete content, promote approved artifacts to a secure zone, and send notifications through email, Jira, or Microsoft Teams.
Stay informed and accountable
The Notification Center provides real-time status updates and quick links to completed scan results.
The Audit log records scan, configuration, user, and sign-in activity for operational visibility.
User management helps administrators control who can access the deployment.
Syslog supports centralized monitoring and logging.
Get started
Add a service connection for a source code, container, or binary platform.
Review the built-in Default Workflow or create a custom workflow for tailored scan behavior and remediation.
Trigger a scan, then explore the results in Reports and track your overall posture on the Dashboard.